Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2019-11396
Avira Software Updater vulnerability analysis and mitigation

Overview

A local privilege escalation vulnerability was discovered in Avira Free Security Suite 2019's Software Updater (version 2.0.6.13175 and earlier). The vulnerability (CVE-2019-11396) was disclosed on August 29, 2019, and stems from permissive access rights on the SoftwareUpdater folder that are incompatible with the privileged file manipulation performed by the product (Full Disclosure).

Technical details

The vulnerability allows unprivileged users to exploit improper access control (CWE-284) through the SwuConfig.json file creation process. An unprivileged user can replace these files with symbolic links to arbitrary files. When an update occurs, a privileged service creates a file and sets its access rights, offering write access to the Everyone group in any directory, which can be leveraged for privilege escalation (Full Disclosure).

Impact

The vulnerability allows an unprivileged local user to obtain SYSTEM privileges on affected Windows systems, effectively providing complete control over the system (Full Disclosure).

Exploitability

The vulnerability requires local access to the system and can be exploited by an unprivileged user through manipulation of the SoftwareUpdater folder permissions and symbolic link creation. The attack requires user interaction to trigger the update process (Full Disclosure).

Mitigation and workarounds

The vulnerability was reported to Avira on April 15, 2019, and after several attempts at fixes, was finally patched on July 8, 2019. Users should ensure they are running a version of Avira Free Security Suite newer than the affected version 2.0.6.13175 (Full Disclosure).

Additional resources


SourceThis report was generated using AI

Related Avira Software Updater vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-12463HIGH7.8
  • Avira Software Updater logoAvira Software Updater
  • cpe:2.3:a:avira:software_updater
NoYesMay 05, 2020
CVE-2019-11396HIGH7.8
  • Avira Software Updater logoAvira Software Updater
  • cpe:2.3:a:avira:software_updater
NoYesAug 29, 2019
CVE-2019-17449MEDIUM6.7
  • Avira Software Updater logoAvira Software Updater
  • cpe:2.3:a:avira:software_updater
NoYesOct 10, 2019

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management